Skip to content

Security Vulnerability: gopkg.in/yaml.v3 #154

@sanjayjohn

Description

@sanjayjohn

gopkg.in/yaml.v3 is a YAML support package for the Go language.

Affected versions of this package are vulnerable to NULL Pointer Dereference when parsing #\n-\n-\n0 via the parserc.go parser.

v0.10.0 is still on an outdated version: https://github.com/slok/go-http-metrics/blob/v0.10.0/go.mod#L59

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions